CHFI v3 Module 22 Investigating Web Attacks.pdf

(2081 KB) Pobierz
Computer H ki
C
Hacking
Forensic Investigator
Module XXII
Investigating Web Attacks
Scenario
Three Russian citizens were charged with extorting money from U.K. e-
commerce companies on October 4 2006.
4, 2006
Ivan Maksakov, Alexander Petrov, and Denis Stepanov were accused of
receiving $4 million from UK firms. The trio concentrated on U.K.
Internet gambling sites, collecting information about British web casinos
and bookmakers’ offices using spy software designed by one of the
members of the crew, and then demanded ransoms from the owners
of such websites under the threat of denial-of-service attacks. During
their six months of activity, the Russian trio attacked over 54 web servers
in 30 different countries.
The U.K. National Hi-Tech Crime Unit (NHTCU) and the Russian
authorities investigated this case and arrested them.
Source: http://www.zone-h.org/content/view/14210/30/
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
EC-Council
Case Study
EC-Council
Source: http://news.com.com
/
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Module Objective
This module will familiarize you with the following:
Indications of a web attack
Types of web attacks
Investigating attacks
Responding to a web attack
Web l
W b logs
Investigating FTP Servers
Log File Investigation
og e
est gat o
Investigating static and dynamic IP address
Tools
Investigating DNS Poisoning
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Module Flow
Indications of a Web Attack
Types of Web Attacks
Responding to a Web Attack
Investigating Attacks
Web Logs
g
Investigating FTP Servers
g
g
Investigating Static and
Dynamic IP Address
Log File Investigation
Tools
Investigating DNS Poisoning
g
g
g
EC-Council
Copyright © by
EC-Council
All Rights reserved. Reproduction is strictly prohibited
Zgłoś jeśli naruszono regulamin